mcp-crash-analyzer

mcp-crash-analyzer

A Model Context Protocol (MCP) server for automated crash analysis using GDB.

Category
访问服务器

README

MCP Crash Analyzer

A Model Context Protocol (MCP) server for automated crash analysis using GDB.

Introduction

This MCP tool analyzes program crashes and provides detailed debugging insights, including register states, memory snapshots, disassembly, and stack traces.

It was created as a learning exercise to explore how the Model Context Protocol (MCP) works and was built largely with the help of AI agents. The tool has been tested on a few specific crash scenarios and produced promising results, though it hasn’t been deeply validated on more complex cases.

I don’t plan to continue active development, but if you encounter issues or have interesting feature ideas, feel free to open a ticket in the Issues tab — if time allows, I’ll take a look. Contributions, feedback, or forks are always welcome.

License: MIT Python: 3.8+

Features

🔍 Automatic Crash Detection - Runs programs and detects crashes automatically
📊 Comprehensive Analysis - Captures signal, location, backtrace, registers, memory
🎯 Smart Disassembly - Full function disassembly with crash location marking
💾 Memory Inspection - Read memory at any address with hex/ASCII formatting
⚙️ Register State - Complete CPU register snapshot at crash time
🏗️ System Info - Architecture, debug symbols, endianness detection
⚡ Session-Based - Load once, query multiple times for detailed analysis

Quick Start

Installation

# Install dependencies
pip install -r requirements.txt

Configuration

Add to your MCP settings file:

VS Code with Cline (~/.config/Code/User/mcp.json):

{
  "mcpServers": {
    "crash-analyzer": {
      "command": "python3",
      "args": ["/absolute/path/to/mcp_crash_analyzer.py"]
    }
  }
}

Claude Desktop (~/Library/Application Support/Claude/claude_desktop_config.json):

{
  "mcpServers": {
    "crash-analyzer": {
      "command": "python3",
      "args": ["/absolute/path/to/mcp_crash_analyzer.py"]
    }
  }
}

Environment Variables

  • MCP_CRASH_ANALYZER_LOG - Custom log file path (optional)
    • Default: ~/.cache/mcp_crash_analyzer.log
    • Example: export MCP_CRASH_ANALYZER_LOG=/var/log/crash_analyzer.log

Usage

Basic Workflow

  1. Load and run a program until it crashes:
load_and_run("/path/to/program", args=["arg1"], timeout=10)
  1. Analyze the crash:
get_disassembly_function()  # See crash instruction
get_registers()             # Check CPU state
read_memory("$rsp", 64)     # Inspect memory
  1. Close when done:
close_session()

Available Tools

Core Tools

  • load_and_run(binary_path, args=None, timeout=10)
    Load and run program until crash or exit

  • get_registers(register_names=None)
    Get CPU register values at crash time

  • get_disassembly_function()
    Get complete disassembly of crash function

  • get_disassembly_range(start_address, end_address, mode=0)
    Disassemble specific address range

  • read_memory(address, size, format="hex")
    Read memory at any address

  • get_system_info()
    Get architecture and debug info

  • get_full_report()
    Get complete crash report

  • close_session()
    Close GDB session

Example Analysis

# 1. Run program
result = load_and_run("/path/to/crashed_program")
# {"crashed": true, "signal": "SIGSEGV", ...}

# 2. See where it crashed
disasm = get_disassembly_function()
# "0x12345: mov (%rax),%ebx ← CRASH"

# 3. Check registers
regs = get_registers(["rax", "rbx", "rsp"])
# {"rax": "0x0", "rbx": "0x7fff...", ...}

# 4. Read stack
mem = read_memory("$rsp", 128, "both")

# 5. Close
close_session()

Example Output

{
  "crashed": true,
  "signal": {
    "name": "SIGSEGV",
    "meaning": "Segmentation fault"
  },
  "location": {
    "function": "process_data",
    "address": "0x555555555234",
    "file": "main.c",
    "line": "42"
  },
  "disassembly": [
    "0x555555555230: mov    %rdi,%rax",
    "0x555555555234: mov    (%rax),%edx ← CRASH",
    "0x555555555236: add    $0x1,%edx"
  ]
}

Common Signal Types

When analyzing crashes, you'll encounter these common signals:

  • SIGSEGV - Segmentation fault (invalid memory access, NULL pointer dereference)
  • SIGABRT - Abort signal (assertion failure, abort() call)
  • SIGFPE - Floating point exception (division by zero, invalid math operation)
  • SIGILL - Illegal instruction (corrupted code, wrong architecture)
  • SIGBUS - Bus error (misaligned memory access)
  • SIGSYS - Bad system call

Requirements

  • Python 3.8+
  • GDB (GNU Debugger)
  • pygdbmi - Python GDB Machine Interface
  • fastmcp - Fast MCP server framework

Use Cases

  • Automated Testing: Detect and analyze crashes in CI/CD pipelines
  • Bug Triage: Generate detailed crash reports with full context
  • Forensics: Post-mortem debugging of production crashes
  • Security Analysis: Analyze exploits and vulnerabilities
  • Learning: Study assembly, understand why programs crash
  • Development: Quick crash analysis without manual GDB sessions

Crash Analysis Workflow

The crash analyzer provides detailed information about program failures:

What Gets Captured

  1. Signal Information - Type of crash and what caused it
  2. Crash Location - Exact function, file, line, and address
  3. Backtrace - Full call stack showing how program reached the crash
  4. Register Values - CPU state at crash time (for low-level debugging)
  5. Local Variables - Variable values in the crashing function
  6. Disassembly - Assembly instructions around crash address
  7. Memory State - Stack and heap inspection
  8. Console Output - All program output before the crash

Analysis Modes

Session-Based (Advanced):

  • Load program once with load_and_run()
  • Query details with individual tools
  • Fine-grained control over what to inspect
  • Best for deep debugging

Full Report (Quick):

  • Get everything at once with get_full_report()
  • Complete crash analysis in one call
  • Best for automated reporting

How It Works

  1. Uses pygdbmi to control GDB via Machine Interface
  2. Maintains session state between load and analysis
  3. Captures register snapshot at crash moment
  4. Provides multiple analysis views (disassembly, memory, registers)

Limitations

  • Platform: Linux/Unix only (requires GDB)
  • Execution: Programs must be executable with proper permissions
  • Reproducibility: Crashes must be reproducible (deterministic)
  • Debug Info: Source line information requires debug symbols (-g flag)
  • Core Dumps: Cannot directly analyze core dumps (run program instead)
  • Single Crash: Analyzes first crash only (doesn't continue after crash)
  • Optimization: Heavily optimized code may have incomplete variable information

Best Practices

  1. Compile with debug symbols: Use -g flag for source line information
  2. Disable optimization during debugging: Use -O0 to preserve variable info
  3. Set appropriate timeouts: Increase timeout for slow-starting programs
  4. Check permissions: Ensure binary has execute permissions (chmod +x)
  5. Use absolute paths: Provide full paths to binaries and source files

🐛 Troubleshooting

Issue Solution
Import error pip3 install pygdbmi fastmcp
GDB not found sudo apt install gdb
Session already running Call close_session() first
Timeout errors Increase timeout parameter in load_and_run()
No debug symbols Compile with -g flag: gcc -g -o program program.c
Missing source info Ensure source files are accessible at original paths
Incomplete backtrace Compile without optimizations: gcc -g -O0 -o program program.c
Permission denied Make binary executable: chmod +x program
No crash detected Check if program requires input or increase timeout
Need debug logs Check ~/.cache/mcp_crash_analyzer.log for detailed logs

📚 Resources

  • pygdbmi: https://github.com/cs01/pygdbmi
  • GDB/MI: https://sourceware.org/gdb/onlinedocs/gdb/GDB_002fMI.html
  • MCP: https://modelcontextprotocol.io/

License

MIT License - Free to use and modify

Author

Magnus Lucchese


Note: This tool automates GDB for crash analysis. For interactive debugging, use GDB directly.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选